CVE-2022-29700: High severity zammad vulnerability
Published Apr 27, 2022
·Updated
A lack of password length restriction in Zammad v5.1.0 allows for the creation of extremely long passwords which can cause a Denial of Service (DoS) during password verification.
Affected Software
1 affected component
Zammad Zammad=5.1.0
Remediation
Patch Available
Event History
Apr 27, 2022
CVE Published
via MITRE·02:47 AM
Data Sourced
via MITRE·02:47 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID of this issue?
The vulnerability ID of this issue is CVE-2022-29700.
2
What is the severity of CVE-2022-29700?
The severity of CVE-2022-29700 is high with a CVSS score of 7.5.
3
What is the affected software?
The affected software is Zammad version 5.1.0.
4
What is the impact of this vulnerability?
This vulnerability allows for the creation of extremely long passwords and can lead to a Denial of Service (DoS) during password verification.
5
Is there a fix available for CVE-2022-29700?
Yes, please refer to the advisory link for instructions on how to fix CVE-2022-29700: https://zammad.com/en/advisories/zaa-2022-03.